mrkeyoor.com_
Thu 01 Oct 08:13 UTC
Self-Hostedevaluationupdated 01 Oct 2026

Spun review

Spun is a Linux music player that presents local, YouTube Music, Cider, Jellyfin, Navidrome, and Subsonic playback as animated CDs, records, cassettes, or a recorder. Its code is visible and modifiable under PolyForm Noncommercial 1.0.0, but the README correctly says this is source-available software, not OSI-approved open source.

Verdict

Our Spun helper run installed 42 packages in 18 seconds and built in 6 seconds, but pytest collected 0 tests and exited 5, so it does not establish that the C++ player works on our box. Try Spun if its CD, vinyl, cassette, and recorder interfaces are the reason you want a music player and you accept a source build. Choose an alternative for commercial use, binary packages, or a longer cross-hardware record.

We ran it

Lab card: what happened when we ran SpunScreenshot of Spun (github.com/yappologistic/Spun)
Install✓ · 18s42 packages · 64 MB
Build✓ · 6s
Tests✗ · 6s0 passed · 0 failed of 0 (pytest)
Known vulns0(pip-audit)
Repo200 files~21,951 lines of source · 5.8 MB · 0 CI workflows · tests dir

Answers from our run

Does Spun build from source?

Dependencies installed in 18 seconds (42 packages), and the build succeeded in 6 seconds. We cloned commit d4448ec into a clean Debian container with 3 CPUs and no project-specific setup.

Do Spun's tests pass?

Yes: 0 of 0 passed when we ran the project's own test command (pytest). Some failures need services or credentials a bare container does not have.

Does Spun have known vulnerabilities in its dependencies?

pip-audit found none in the dependency tree at the time of our run.

Who should not use Spun?

Commercial products or services: PolyForm Noncommercial restricts use outside its listed permissions, and no commercial edition is offered.

What are the alternatives to Spun?

Strawberry, Tauon Music Box, Feishin. Our Spun helper run installed 42 packages in 18 seconds and built in 6 seconds, but pytest collected 0 tests and exited 5, so it does not establish that the C++ player works on our box.

Setup2/5Source-only Qt build; our Python helper test collected nothing
Docs5/5Detailed distro, source, integration, privacy, and test guidance
Community3/5434 stars with issue and pull-request activity in September
Maturity2/5No release or CI, plus an open Fedora 3D crash report

Who it’s for

Linux listeners who care as much about a tactile player interface as library management.
Jellyfin, Navidrome, or Subsonic users who want a native desktop client with animated media views.
Cider users who want a separate front end for Apple Music playback and browsing.
Qt developers comfortable compiling a young desktop application from source.

Who it’s NOT for

Commercial products or services: PolyForm Noncommercial restricts use outside its listed permissions, and no commercial edition is offered.
People who want a packaged installer: the README says Spun builds from source, and GitHub has no published release.
Ubuntu users unwilling to install a newer toolchain: Ubuntu 22.04 and 24.04 repositories lack the required Qt 6.8+ and TagLib 2.0+ according to the setup guide.
Buyers treating our lab result as a desktop-player test: we measured only helper/, and pytest collected 0 tests before exiting 5.
Users depending on the 3D renderer across hardware: open issue 25 reports a Fedora crash in 3D mode, while the regular 2D player remains the safer trial.

Setup reality

Our sandbox tested commit d4448ec inside helper/. Installation took 18 seconds, added 42 packages, and used 64 MB; its build check passed in 6 seconds. Pytest then exited 5 after 6 seconds because it collected 0 tests, reporting 0 passed and 0 failed. Pip-audit found 0 known vulnerabilities.

That helper powers optional YouTube support, not the C++ desktop application. Spun itself needs Linux, a C++20 compiler, CMake 3.22 or newer, Ninja, Qt 6.8 or newer, TagLib 2.0 or newer, and optional Qt Quick 3D. There is no packaged installer.

The repository had 200 files, about 21,951 source lines, and a tests directory, but no CI workflow or Dockerfile. Main-player tests also need Qt components, display or audio facilities, and sometimes D-Bus or disposable media servers.

Four physical-media views are Spun's reason to exist

Spun turns album artwork into a spinning CD, record, cassette, or TP-7-style recorder. The controls follow the object: the vinyl needle seeks, cassette reels move, a disc lid opens, and the recorder wheel can be dragged. Optional 3D bodies add cases, tonearms, lighting, and a small mixer. If those details sound unnecessary, another player will be easier. They are the product here, not decoration around a conventional library screen.

The sources are unusually broad for a new player. Local files stay in place. Cider supplies Apple Music playback and authentication through its local API. Jellyfin, Navidrome, and Subsonic connections provide remote libraries, while anonymous YouTube Music browsing uses an optional Python helper. Each account or source keeps its own queue. That variety is useful, but every path brings different authentication, buffering, permissions, and failure modes.

Source-only installation needs Qt 6.8 and TagLib 2.0

There is no packaged installer or GitHub release. Arch, CachyOS, and Fedora get explicit dependency commands, while Nix users have a flake. The general build requires a C++20 compiler, CMake 3.22 or newer, Ninja, Qt 6.8 or newer, and TagLib 2.0 or newer. Qt Quick 3D is optional and can be disabled if the visual models are not worth the extra dependency.

Ubuntu is the awkward case. The README says the default repositories in 22.04 and 24.04 do not supply new enough Qt or TagLib packages, so users must install a newer Qt SDK and build TagLib separately. That is substantial setup for a music player. The launcher also points back to the cloned folder, which means moving the source requires reinstalling the launcher entry.

What happened when we ran it

Our sandbox tested commit d4448ec in the helper/ directory, not the C++ desktop app. The Python installation took 18 seconds, added 42 packages, and used 64 MB on disk. Its build check succeeded in 6 seconds. The Debian container had 3 CPUs, 8 GB of RAM, no secrets, and no elevated privileges. Pip-audit reported 0 known vulnerabilities.

The test command failed with exit code 5 after 6 seconds. Pytest reported no tests ran in 0.00s, which means 0 passed and 0 failed because it collected 0 tests. The repository does contain a tests directory, but there was no Python test for this helper path. Calling that a product regression would be wrong. Calling it a green test run would be wrong too.

The checkout contained 200 files, roughly 21,951 lines of source, and 5.8 MB before helper dependencies. Our scan found no CI workflow and no Dockerfile. The main CMake project registers native tests when built with testing enabled, but those checks need the Qt toolchain and, depending on the case, a display, audio session, D-Bus, or disposable Jellyfin and Navidrome servers. We did not run them.

Every music source carries a different boundary

Cider must remain running for Apple Music, and its local API needs separate approval for search and queue access. Spun says it does not ask for the Apple Music password. Jellyfin tokens can go into the desktop keyring, while Subsonic uses salted token authentication and may store a remembered password there. Remote servers should use HTTPS. These are reasonable choices, but the desktop keyring and server permissions become part of setup.

The YouTube route is unofficial and depends on ytmusicapi plus yt-dlp. It has no Google login or account synchronization, and its local favorites and history stay on the device. Network or YouTube changes can break playback until those dependencies catch up. Our 42-package helper install is the measured cost of that optional path; local files and Cider do not require it.

The license rules out ordinary commercial adoption

Spun uses PolyForm Noncommercial 1.0.0 for its original code and assets. The README explicitly calls it source-available and says the license is not OSI approved. Personal use and the other listed noncommercial or institutional cases are permitted under the license terms. A company that wants to bundle, sell, or operate it should not assume the visible source grants the same rights as MIT, Apache, or GPL software.

Project health is active but brief. GitHub showed 434 stars, 20 combined issues and pull requests, and a last push on September 16, 2026. A Fedora user reported a crash after enabling 3D, and issue 5 still asks for CI. Pull-request activity continued through September 23, including distribution setup work. Test the 2D player first, then enable 3D on your actual graphics stack. The simulated hardware is Spun's best reason to accept the source build, and also the part most likely to expose driver differences.

Alternatives

ProjectWhat it isPick it when
StrawberryA desktop music player and library organizer focused on local collections and audio quality.pick this instead when library management and established packaging matter more than animated physical-media views.
Tauon Music BoxA Linux desktop music player for local libraries and network sources.pick this instead when you want a mature general Linux player with less emphasis on simulated hardware.
FeishinA desktop and web client for self-hosted music servers such as Navidrome and Jellyfin.pick this instead when a self-hosted server library is primary and local physical-media visuals are optional.

What people are saying

  1. [velocity-scout] yappologistic/Spun

Sources

  1. Spun repository and README
  2. Measured commit d4448ec
  3. Fedora 3D crash issue 25
  4. CI request issue 5
  5. openSUSE build dependency pull request 31

More self-hosted reviews

bankmcp · 8086-xcheck-system · fanzha-ai-proxy · homarr · search-plugins · vphone-web · the whole board →